{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/forensic-obstruction/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Amazon Detective"],"_cs_severities":["low"],"_cs_tags":["cloud","aws","defense-evasion","forensic-obstruction"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eThe deletion of an Amazon Detective behavior graph via the DeleteGraph API is a defense evasion technique that targets an organization's forensic capabilities. Amazon Detective consumes logs from AWS CloudTrail, VPC Flow Logs, and Amazon GuardDuty to provide automated security insights and visual relationship mapping. Because the deletion of a behavior graph is an irreversible operation, it effectively destroys the historical analytical context required for post-compromise investigation.\u003c/p\u003e\n\u003cp\u003eThis activity is significant for defenders because it is rarely performed as a routine maintenance task. When observed in production environments without accompanying change management records, the deletion of a Detective graph likely indicates an attempt by an adversary to obstruct security teams, hide their movements, or disrupt the incident response timeline. Security teams must monitor for this API call and correlate it with other environmental changes, such as the disabling of GuardDuty or the modification of logging configurations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to an AWS environment through compromised credentials or exploitation of a misconfigured resource.\u003c/li\u003e\n\u003cli\u003eAttacker performs discovery to identify enabled security services and monitoring capabilities, including Amazon Detective.\u003c/li\u003e\n\u003cli\u003eAttacker evaluates existing IAM permissions to determine if they possess the authorization to modify or delete security infrastructure.\u003c/li\u003e\n\u003cli\u003eAttacker executes the \u003ccode\u003eDeleteGraph\u003c/code\u003e API call, resulting in the permanent destruction of the behavior graph and historical data.\u003c/li\u003e\n\u003cli\u003eAttacker proceeds with further malicious objectives, such as data exfiltration or persistent resource deployment, now unhindered by Detective's behavior monitoring.\u003c/li\u003e\n\u003cli\u003eAttacker clears or attempts to minimize trace artifacts while the environment's forensic investigation capabilities are degraded.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deletion of an Amazon Detective behavior graph results in the permanent loss of historical security analytics and the inability to use graph theory-based investigation tools for existing incidents. This creates significant blind spots for incident responders who rely on Detective to trace resource interactions and identify the scope of an adversary's activity. The impact is primarily a severe reduction in forensic capability, which complicates incident scoping and increases the time required for threat hunting and remediation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to detect and mitigate the unauthorized deletion of security services:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement a detection alert for the \u003ccode\u003eDeleteGraph\u003c/code\u003e action in AWS CloudTrail using the provided Sigma rule.\u003c/li\u003e\n\u003cli\u003eApply Service Control Policies (SCPs) that restrict the \u003ccode\u003edetective:DeleteGraph\u003c/code\u003e permission to a limited set of break-glass or senior administrator identities.\u003c/li\u003e\n\u003cli\u003eAudit IAM permissions across all accounts to identify identities with excessive access to security service management APIs.\u003c/li\u003e\n\u003cli\u003eReview change management logs when this alert triggers to differentiate between authorized environment decommissioning and malicious activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T13:55:50Z","date_published":"2026-08-26T13:55:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-aws-detective-graph-deletion/","summary":"Attackers with high-level IAM permissions may delete Amazon Detective behavior graphs to impair forensic investigations by destroying historical relationship mapping and telemetry analysis data.","title":"Defense Evasion via Deletion of Amazon Detective Behavior Graphs","url":"https://feed.craftedsignal.io/briefs/2026-08-aws-detective-graph-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Forensic-Obstruction","version":"https://jsonfeed.org/version/1.1"}